Authenticated arbitrary file upload via a System REST API requiring administrator permission. (CVE-2025-13590) | HOL Guard CVE